Hi, Paul Williams here, producer of UFO Desk. UFO Desk is on hiatus, but we'd sure like you to come by and visit us on the World Wide Web. You can find UFO Desk and all of your favorite WBAI producers at www.wbaifree.org. That's the website of the WBAI producers. At that site, you'll find OutFM, Our Americas, Earthwatch, Liquid Sound Lounge, Jay Smooth's Underground Railroad, and many others, and of course, UFO Desk. So please visit us at www.wbaifree.org, and special thanks to Pamela Summers for putting it all together. And it's 8 o'clock on a Wednesday, no, it's 8 o'clock on a Tuesday. You know, I never know what day it is around here, but I do know it's time for Off The And good evening to everybody. It's another edition of Off The Hook, with Emanuel Goldstein and FiberOptic. Greetings. Well, it's been a busy week for us, organizing this conference, which will be aired live here on WBAI on August the 9th, that's Saturday, August 9th, at 6 p.m., from 6 to 8. This is going to be wild. This is going to be hacker history. There has never been a conference quite like this, with so many people showing up from all different parts of the world, and linked with another conference just as big in another country, linked via, I guess, what's the best way to say it? ISDN lines, video links, things like that. It's going to be really cool. It's too late to pre-register, but it's not too late to actually show up on the day of the conference. We're setting up August 8th, which is a Friday. We're setting up all throughout the day, and we can certainly use all the help we can get as far as network ability, things to contribute. We're also, of course, looking for interesting speakers. A lot of our speakers, panel sessions, are taken at this point, but we're flexible, and we can always squeeze things in. We'll be doing mostly video things and testing with the overseas connection on the video display unit on Friday night. The actual conference begins Saturday around noon. Keynote speaker is Brock Meeks, who many of you know as an investigative reporter who finds out quite a lot of things in the hacker world, and now he can be seen on MSNBC, just another example of how people in this world keep moving on to more and more interesting things. So we have that to look forward to. We have all kinds of other seminars and displays. We'll be having a network unlike any other network I think we've ever seen with computers of all sorts, old computers, new computers, supercomputers, all hooked together in a huge room and all put onto the internet at high speeds. Someone actually went and created a Quake room. I don't know how many of you out there play Quake, but someone made a room that looks exactly like the conference area that we have for this conference. So people can be running around playing Quake and actually playing in the real environment that they're in, except they won't be running around hopefully with all kinds of weapons and things, shooting monsters. But it's developing into something that we saw once before in 1994 at the Hackers on Planet Earth conference, and it's magic when everybody comes together like this. So if you're interested in being a part of it, it's still not too late to become involved. We don't recommend, in fact we strongly prohibit you from pre-registering at this point because the deadline for that was the 15th, and I believe today's date is what? The 15th. Is it the 15th or the 16th? It's the 15th. It's the 15th. Okay, so I guess technically you have four hours if you want to run down to the post office on 8th Avenue there and mail it before midnight. I guess you could get away with it, but after that, no. No, no, no. We just will not allow it. So the conference takes place at the Puck building, which is that really neat looking building down on the corner of Houston and Lafayette. With the statue of Puck on it. With two statues of Puck on it. Two statues. Yes. One on each corner. In fact, I am told that the previous issue of 2600 features that building on its cover. I haven't even seen it yet, so I don't know. Really? No one shows me anything. But I understand, yes, there is some interesting artwork there featuring that building. We'll be on the whole first floor, so you can just come on by any time throughout the weekend. Same cost throughout the whole weekend. It's going to be really interesting. And check our website too, which has all kinds of fun things. www.hope.net. In fact, our webmaster is here. Does our webmaster care to say anything about the website and about who has been perusing it? Hang on, let me figure out what microphone you are. Okay, I think this one. Well, it might be interesting to note that we have received a lot of mail hits. In other words, from hosts in the mail domain, which is the U.S. military. The U.S. military. For those of you out there that have no idea what we are talking about, the internet is comprised of all different domains. .com is commercial. .gov is governmental agencies. .edu is educational. .org is non-profit organizations. But .mil, .mil is the darkest and most mysterious of them all. And when you have a website, you can see who is actually connecting to you. And in our case, we have been getting... Give us some examples. What kind of military people have been... Not the people, but the organizations. We don't give out people's names. Well, I went through the list of hits and grepped for .mil so that I could find all of the mail machines. And among the hits are DARPA, which is the Defense Advanced Research Projects Agency, which is responsible for a lot of military research. We got ACERT, A-C-E-R-T, which is the army version of CERT. And they do computer security for the military. We got hits from MISSI, M-I-S-S-I, which is the Multilayer Information Systems Security Initiative, which is part of the NSA. And they're responsible for managing crypto for the government and limiting our use of it. Interesting. And they have an interest in this conference. Oh, they sure do. And some of these places have hit us on multiple occasions. So they're looking for new updates. Yeah. And we're providing them. Oh, in fact, one of the updates that are there right now is a list of those agencies. So they'll be very interested in that, I'm sure. And we have links to all of them. So their hits will be going up as well. Yeah. Of course. It's like a communications exchange. And hopefully, you know, these people will be showing up one way or another. Hopefully, they'll take part in the conference. And they'll say, yes, I'm from this agency, which doesn't officially exist. This is what we do. Or something like that. It would be nice. Unfortunately, I have a feeling that many of them will be incognito. Well, you know, many of us are incognito, too. But we still recognize each other. And we know who's on what side. I suppose. Yeah. So, okay, that's one of the examples. What else can we look forward to on the website, www.hope.net? Oh, boy, there's going to be lots of fun stuff. During the conference, we actually plan to have live updates of all the nifty stuff that will be going on. We're going to have a bunch of folks running around with digital cameras taking pictures of all the big events that happen. And moments after they happen, I'll be writing stories about them. And they'll be up on the website. So if you can't manage to come to Beyond Hope. This is not an encouragement not to come to Beyond Hope. Well, we certainly hope you do. Because you won't have nearly enough fun if you don't come to the conference. But if for some bizarre reason you can't. If something happens and you're laid up in a hospital bed somewhere and you have net access there or whatever, and you feel like following it there, or if you're in some distant part of the world. That's right. If that is indeed the case, you can visit the website and actually see what's going on hour by hour. That sounds good. How about leading up to the conference? Any other new nifty things that we can see? Or are they all secret? Well, there's the Beyond Hope Ride Board. Yes. Which maybe needs a little publicity at this point. Well, actually, I think most of the people in the area probably can get rides. Because, you know, there's mass transit and all. But for those of you outside the listening area, I guess you're hearing this on real audio. Or maybe you know somebody that's kind of far away. I guess some people on Long Island, New Jersey, upstate New York might have a little bit of difficulty. Connecticut. All right. Well, if you have any friends who are having a hard time getting to Beyond Hope, or maybe can offer somebody outside of the New York metro area a ride there, there's the Beyond Hope Ride Board. And if you go to the main page and click on Features, it's right there. And basically you can enter your information as far as your name and e-mail address. You don't have to give your real name, of course. And where you are and whether you can offer a ride or need a ride. And it will put you into our Beyond Hope Ride Board database. And it's searchable. And it helps people hook up for carpools. And people have been trying to do this on the Beyond Hope mailing list for a very long time with limited degrees of success. And this kind of automates the whole process and makes it a lot easier and maybe even a little more fun. All right. Okay. We're also going to be having guides to interesting places in the area. Kind of an interactive tour of the Lower East Side. That's right. And we'll be able to actually roam the streets of New York in our Beyond Hope Guide to New York. And no fear whatsoever of the evils that lurk. Except maybe for some sort of evil net things that might happen. No, actually, that's a really good part of town. And that's where I think a lot of people will have a really good time. So that's happening August 8th, 9th, and 10th. So stay tuned for more details on that. And, of course, the live broadcast August 9th at 6 p.m. here on WBAI. Well, Farber, as far as what's been happening with you, you were in the Wall Street Journal last week. What's up with that? Yes, I was. I think the first line of that article was kind of funny. I thought the first line of that article was a little stupid. Yeah, it was a little stupid, but in a funny way. Yeah, I guess depending on your sense of humor. Fortunately, the main body of the article was a lot more beneficial and to the point. Basically, what happened was I was in the process. We mentioned it a little bit last week. I was in the process of doing a security review or a so-called penetration test. And you penetrated quite a bit, didn't you? Yeah, I was quite apt at the penetration process. More apt than you expected to be because you expected to only do it locally and somehow you went out to the whole world. Basically, I had gotten into a bunch of machines at this particular client. And I was in the process of attacking their Usenet news server. And I had recognized from the header of their news server, from the banner rather, that they were running a rather dated version of the Internet network news software, INN. And I proceeded to send a forged control message, which control messages are what are sent normally by news administrators to create new news groups, to delete news groups, to cancel posts and so on and so forth. It was a forged message that basically executes shell commands, which are embedded in the body of the post. And in the header of this message, I set the distribution to be a local. And normally when the distribution of a message is set to local, it is only supposed to be distributed to those news groups that are considered local. It's not supposed to leave the machine and go out to Usenet servers, news servers all over the world, which is exactly what happened. Suffice to say, due to misconfiguration in the news server software at my client, my exploit was posted to the Usenet at large. And to this day, I am still getting password files. You got some more today. I've been getting them every day, even though it's been in the Wall Street Journal. I've posted all about it on numerous security and administrative news groups on Usenet itself, saying exactly what I did, why I did it. It's not anything new. And then if you're running anything short of INN version 1.5.1, which is the latest version, then you've got a problem. And I probably have your password file. I've already notified Cert about it multiple times. And the problem I had with Cert, and the problem I still have with Cert, is initially they were very receptive to the whole thing. And then they said they want you to do it for them. Yeah. Initially, they said that it's great. You actually have all this information. Usually, if a professional like yourself actually got this info by mistake, then they would have just deleted it because they didn't want to get into any kind of trouble. But you actually held on to it. You have a concise list of every single vulnerable news server in the world. You have more power than all of us combined. Right. So the guy I spoke to thought it was great and said that they could put the gears in motion to notify all these sites and to send him the complete list. I got a call back about an hour later from his boss saying basically a completely different story, which was that Cert does not have the facilities to respond to all those people. The mental facilities? I think so. Because I said, well, you run the Cert mailing list. That goes out to a few thousand people all over the world. And they said, well, you know, sir, the problem isn't mailing all those people. The problem is dealing with the responses we would get from those people. Well, they usually ignore responses anyway. Yeah. So I don't think that's much of a problem. And I don't understand because if you have a mailing list that goes out to a thousand people, I would tend to think that some of those people are going to reply if they don't have a clue about what to do about the problem. So I was really rubbed the wrong way. So they're in charge of this kind of thing, but they don't want to do it because they can't handle the responsibility, is basically what they're saying in so many words. Yeah. And they wanted me and my client to handle doing it. And I said, look, I'm an independent consultant and my client is a nonprofit organization. Now, wait, wait. Let's go back a few years. What if this was M.O.D. we were talking about? What if you were still in this hacker group and you guys had done it? Would they expect M.O.D. to go out and take care of this problem just because you're working for a client now? Do you have to do all this work? I mean, let's just say you're a bunch of hackers doing this on your own. Now the rules change. Well, I'm a professional now. The rules are different. So because you're a professional now, you're expected to do their work for them. Yeah. Whereas if you're a hacker, you just get thrown into jail and blamed for it. Yeah, I guess so. I'm understanding how it works. Well, it's not to say I couldn't. Contacting the Wall Street Journal was actually done by me. It wasn't done by them. Right. I contacted them and I wanted to put some damage control on the thing before it blew all out of proportion. That was only like a day or two after the incident happened. But did you know that there was another article based on that Wall Street Journal article that came out in some other magazine? I have not seen this. I heard about it online. I heard about it too. And it's incredible. Totally twisted it. Let's talk about manipulation of the language. They made it as if you were caught doing something and that you were thwarted somehow. What else did they say? They said all this stuff that just was not true and totally... Yeah. I mean, they basically totally spun the thing around into a different direction and made you into somebody you weren't. Made SIRT into somebody they weren't. I don't really care because, I mean, the way I would describe people like that, and I'm pretty sure we can use this word, schmucks. Yeah, you can use that word. I don't think that's a banned word yet. Yeah, that's on the list of words we can use. Yeah. The list of words we can use is now shorter than the list of words we can't use. Yeah. So we keep that up now. Those are just schmucks, okay? Because it went out over the Wall Street Journal. The reporter got the story correct with the exception... There's a minor detail which didn't really take too much away from the story is that the password files that I got that weren't shadowed, whereas the encrypted passwords weren't stored in a separate file altogether that I wouldn't have been able to access, the password files that I did get that were not shadowed had encrypted passwords in them. The article was probably a little misleading to people that didn't know anything about the way passwords are stored on Unix. It made it sound as if my mailbox was filled up with thousands of people's passwords. Well, it also made it seem like having you work as a computer consultant was some kind of ultimate irony. Yeah. It couldn't possibly be conceived of by any rational thinking person. Yeah, I think the exact words were, of all things. Of all things, yes. Yeah, I think the irony which was understood by me and the writer, I don't think was conveyed very well in the article probably after it reached the editor. I actually brought up the irony and I wanted the irony included in the article and it didn't really come across properly. The irony is obvious that I got prosecuted for doing much the same thing that I do now for a living. Yeah, I think you phrased it very well in the article. Yeah. The difference is you just would have been thrown in prison for the same thing a couple of years ago. Yeah, it's really ridiculous. On the lighter side of things, forgetting CERT, there were two organizations that responded in a positive light and I was surprised and I think you'll be surprised as to who they were. The first positive response that I got which showed what seemed to convey a genuine concern was the military's assist. Really? And assist is an organization that's sort of like the equivalent of, yet another equivalent of sort of a CERT for the military, for .mil sites. And somebody from there contacted me about getting in touch with him. Hang on, let me ask our webmaster, have they accessed our website, these assist people? Assist specifically? I believe assist is assist.gov and not .mil. No, it's in .mil. Well, then they haven't hit us yet, but I'm sure they will. Yeah, keep an eye out for them. All right, continue with your story. Yeah, so someone from assist contacted me and basically he wanted me to notify him of all the .mil sites that, you know, which were news servers that were vulnerable to this attack. And luckily for the integrity of our nation, there were only about four of them that were actually bona fide .mil sites in the United States that did in fact mail me back. I understand there are some entities in foreign military organizations that are fit to be tied about all this. Yeah, that is true. Yeah, one of them was the Australian Navy. Yeah, they're calling out your name and with not so nice things surrounding them. Yeah, there were a couple of military and governmental organizations. I don't think you ought to go over there anytime soon. No, I wasn't planning on it. But the other one, which I think you'll be shocked about, was the U.S. Senate. The U.S. Senate? The U.S. Senate contacted me in email. The U.S. Senate? Are you sure this is the U.S. Senate and not some hacker? No, the U.S. Senate apparently read the article. The whole U.S. Senate or just like somebody in the Senate? A representative of a Senate subcommittee. Okay. And basically she first contacted the guy in charge at the place I was doing the job for. Right. And then he wanted, sorry, she wanted him to contact me in order to get a hold of her. Wait a minute, wait. She wanted him to contact you? She talked to him and basically said to tell me to call her. What if you weren't there? How would you? He emailed me the information. He emailed you the information that she called him wanting you to call back him to speak to her? Okay, let me explain. She emailed him first. Right. They spoke on the phone. No, we know that. Right. They had a nice conversation. She asked him to notify me by phone and by email with her original message to contact her. Well, how did you get into this? Because I'm the reason why she contacted them. Oh, right, okay. No problem. Right. So you talked to her? I haven't talked to her yet. Well, what are you waiting for? For God's sake, this is the Senate. Oh, yeah. I mean, these boats don't come along very often. You know, you better jump on. All right, so. Well, anyway. Yes. I do plan on contacting her. Basically, she just wanted to know. Uh-huh. A bit more generalized of a question, which was where I thought the weaknesses actually lie in the information infrastructure. Really? You might find yourself testifying before a Senate subcommittee, and I want to warn you about that. Oh, yeah. That can be kind of, well, I was before a House subcommittee. Yeah. So it's like, you know, a bunch of Geraldos talking to each other. Yes, as I remember, you made really good friends with Edward Markey. I waited for him outside, but I never showed. Meet him after class. Yeah. 212-279-3400 is our number. I know we promised we were going to take more phone calls this week than we did last week, because we only had two people on last week. Yeah. And they're, like, people that always call up. So hopefully new people will call in this week, and we can answer some questions and hear some interesting remarks, and maybe people want to talk about what they're going to do with the HOPE conference or whatnot. 212-279-3400, look at it, all the phone lines are just instantly filled. You should pick a random line, not the first one, because we know who that's going to be. Yeah, but, you know, the thing is, I've done that before, and somehow it just winds up there all the time. Remember that last time we tried randomizing the phone things, and we just got nothing but clicks and weird noises? Yeah. Yeah, but wasn't that the Claude episode? Yeah, well, that happened later, where he unplugged us from the air. Yeah. Yeah, well, that's another thing. We've been Clauded. Yes. That was the famous Mudge episode. Mudge will be at Beyond HOPE, and he'll be hopefully not unplugged there. 212-279-3400, so let's go to a random call. Random. Let's go to this one over here. Good evening, you're on the air. Yes, hi. I'm not totally clear on exactly what you guys accomplished. It sounds like you were able to access a bunch of secret passwords. No, you see, okay, that's the other thing. The article said that he accessed passwords. Now, by accessing a password file, you are not actually accessing the passwords. You're getting an encrypted string, which you could then run through a fairly sophisticated program to crack it, if it matches some pattern like, say, a word in a dictionary or something else that could be guessed. You can't always crack every single one, but I imagine you could crack quite a few. You haven't actually cracked any of these passwords. No, I haven't run any password crackers on them. I don't really have any interest in running any crackers on them. I see, I wasn't too clear on exactly what it was he had accomplished. So what exactly did he accomplish there? He got certain, like, halfway there, almost? Well, he executed a command, basically, that said, send me this file, and in many cases, the way it should be now, that file should point to another file, which is inaccessible. In many cases, however, that did not happen. Would you say more than half you got the actual password file as opposed to a pointer? Well more than half. Well more than half. So that means... That in itself is a security hole. Yeah, that's what I was going to say. This means there's a tremendous breach in the overall security of not only government, but medical records. In other words, we're living in a goldfish bowl. Let's get one thing straight before we get a little carried away here. There are no medical records stored on the Internet. Oh, not on the Internet. Are you sure about that? There's a lot of stupid people running things. No, there are no medical records on the Internet. I mean, Netcom kept 20,000 credit card numbers there. You know, who knows? If Netcom was a hospital, I'd hate to think what would happen. The insurance industry run a medical database that's accessible by insurance industry people. When you sign a waiver, I once read an article in the Times that once you sign a waiver, say, for a life insurance policy, for instance... We're going to have some private investigative type people at Beyond Hope that will be showing you exactly what it is you can access, what has been accessed in the past, and what the whole, you know, potential of this thing is. But what's scary, basically, in the computer age, is the kind of goldfish bowl aspect of the lies. Very little is private anymore unless you go, like, say, you go to a psychiatrist and you tell him you made a suicide attempt. He puts that in your treatment plan. It goes to the insurance company. It then goes into the computer database. You apply for life insurance. They access that. They say, oh, no, we're not giving this guy life insurance. He's a high risk because he made a suicide attempt. So a lot of people now are going to, let's say, a therapist, but paying cash because they want to avoid that whole pitfall of having the insurance industry have access to all their medical records. It's very hard to be anonymous these days. That's one thing I have to give the gypsies credit for. It is amazing that in this day and age, a group of people can remain invisible. Yes. Literally invisible. A bunch of them going through downtown earlier today, and I'm just enthralled by the whole thing. They took your wallet. No. I'm joking. But it is amazing. Gypsy jokes now. No jokes. But it is amazing that people can stay invisible in this database kind of age that we live in. I give them credit for that. I really do. Anyway, the show is very interesting, though I don't fully understand totally what you did, but I have a general idea. It's sort of like you got halfway to accessing, it sounds like, passwords. Yes, okay, not to understand exactly what he did, but as long as you don't jump to a conclusion as to what you think he did and say that as fact, which is what a lot of journalists seem to do. The impression I got was that he was able to get secret passwords to access secret files. Basically, it was a step in that direction. He could have decrypted the passwords. To work to get the passwords, like you said. But then he would have had to have logged in using those passwords and then found the right files, then gotten root, then gotten the system to its knees, you know, that kind of thing. It's amazing. Remember that movie, these kids hack into the Pentagon computer and almost start a nuclear war? It was a dumb movie, but the implications were scary. I think it was called War Games. That's right. That's what it was. War Games is a good film. It was okay. It was fun. It wasn't bad. Parts of it got a little hokey, but the premise is interesting. It was actually NORAD, not the Pentagon. NORAD, I'm sorry. That's right. It wasn't NORAD. It's been a long time since I saw the movie. It was the North Atlantic Radar, whatever they call it. The net that handles it. Well, that, too, was scary because we still haven't overcome the risk of an accident, a nuclear war. The net war on such short notice, standby. The launch times are getting shorter and shorter. Looking desperately for an enemy. Right. You can't seem to find any. The war on drugs superseded the evil empire. They're using that as a pretext to encroach on people's civil rights and civil liberties and bust their doors down looking for some illicit drugs instead of fighting communists. Drugs are the enemy. Thank you very much for calling in. All right. 212-279-3400. I heard a thing on C-SPAN the other day. I forget what the senator was. They were asked, would you support the use of nuclear weapons in the war against drugs? Very definitely. Very definitely, sir. Oh, boy. Where are we going? 212-279-3400. That was a random line that worked out pretty well. Yeah. Let's see if this one does. Good evening. Good evening. You're on the air. Hello? Yeah, speak up. Hi, it's me. I haven't called you guys for a few. Oh, this is a voice in the past. We haven't heard you for at least, what, two months, I think. Yeah, I've been calling all other places, RNN. I was on C-SPAN. You're just making the rounds. You're in demand now. Yeah, but, you know, I couldn't keep away from you guys. Was it truly weak that guy was Rebel you had in the studio live? Or was there, like, a caricature of Rebel? Well, we had basically a sophisticated line installed so that it would seem like Rebel was in the studio. Yeah. It certainly worked. A lot of people were afraid. That was sort of the trippy Summer of Love episode of Off the Hook. Anyway, I'd like an update, if I might, from the show a few months ago with a guy calling in from Atlanta where the security guards hassled him at the 2600 meeting. Has he or any of his cohorts taken any legal or other steps? As far as I know, no legal action has been taken. The meetings have been continuing in relative harmony. If I'm mistaken on that, please fill me in. But I don't think anything else has happened in that situation, which is actually, you know, I think that's the best course. If things can just be kind of, you know, calmed down and these things don't happen again, we don't need to, you know, focus on it for the rest of time. A lot of times people make mistakes and then they, you know, they don't make them again. And that's happened in a few meetings. The next thing is, I think from 92, Fiber had a debate with, I think, what, the New York State trooper who busted him, if you guys recall that. Do you think you're going to be doing anything similar of that ilk soon, some sort of pro and con crossfire type debate? There will be law enforcement types at the conference as well as governmental types. Some of them have expressed an interest in being on a panel. So, yes, there will definitely be some of that back and forth. Another thing, we're talking with people who stand up for what we consider net censorship, what they consider net protection. People who we consider to be spammers, they consider it to be First Amendment rights and a way of advertising. So we're going to have those people there. You're not going to agree with everybody. It's going to make for some very interesting discussion. Great. And the last thing is, I have sort of a weird gold MetroCard story that happened to my mother. She's a senior citizen. She has, have you seen one of those photo ID here for your MetroCards? Yes. She has one of them, and she has been doing it in terms of them deducting 75 cents for the bus and subway. And a week or so ago when she swiped it, it said, balance left 901. Have you heard anything of that? Do you know why they would have a penny on there? I do not know why there would be a penny there, but I do know that they can enter any amount into the machine. They say they can only enter in $1.50 increments at the subway token turnstile. But if you can actually get somebody to work with you inside that booth, and it can happen after you try a few hundred times, they can enter any amount that you tell them, up to the maximum. But they can enter, they can stop at a certain amount. Our webmaster has something to say on that. Once your mother has used up the card, except for that one penny, she should go to the token booth and see if she can get that one penny back. Well, you know, they don't give you money for the cards. They tell you to send it in. No, no. Yeah, send it in. You have to like give cash, and they reapply the money at the subway booths. What do you mean by send it in? Well, they give you an envelope. You send in the card if it's like not working properly. Oh, I didn't know that. And they refund your money or something. I don't know. I've never done it. I did not know that. The last thing is, in August, I'm going with some friends of mine to Maine for the Giant Fish concert at the Abandoned Air Force Base in Limestone. Wait a minute. When is this? When is this? It's the weekend of August 16th and 17th. Okay, that's good. Although, I don't understand. It could be a weekend. Oh, okay, 16th is a Saturday. Right, so we're like going on the Greyhound route. It's like a 10-hour trip. August 9th, you'll be at the Beyond Hope conference. If I can get the money together and if I'm welcome, I thought you guys were sort of ribbing me and making me feel like I'm sort of not welcome on the show, but you don't know what I look like in person. How could you get that impression from us? I'd like to show up, but are you going to take phone calls? First of all, there's going to be a couple of thousand people there, so even if we do rib you, there will be lots of people there not ribbing you. Are you going to take phone calls on BAI when you do the simulcast? We're going to try. I can't guarantee that, but the way it works is we get an ISDN line from here to there. And, of course, that's how we get the signal, the FM quality signal over there. To take phone calls requires somebody in the studio pressing buttons, and we could conceivably do it, but we have to do a lot of testing. The last thing is my friend is hooked up to the World Wide Web, and there are just two websites I want to check out thanks to you guys. Ninex sucks, and, of course, 2600. But for some reason, he has a reconditioned computer, and it takes him, even though he has an internet provider, 30 minutes to get on the web. It could be human incompetence or something, but I'm not going to rest or be reincarnated until I check out those two websites. Okay, well, keep trying. All right, talk to you guys. Take care. All right, take care. Even if it takes 30 minutes, it's worth it, right? Oh, if you can rest and then be reincarnated, not necessarily in that order, I guess it's... You know, I saw this thing on, there was this whole big MetroCard public relations thing this week where they're talking about the transfers, you know, the free transfers between buses and subways. And with every story, every channel had a different story, but, you know, the thing that they always focus on are the people walking through the turnstiles because that's the whole, you know, point of it. You see people swiping the MetroCards going through. With every single one of those, I saw at least one person who had to swipe it more than once. They swipe it, get this really annoyed look on their face, swipe it again. Once, I'm pretty sure I saw someone do it at least three times. And for me, if I was going through that, I'd be doing it interminably because there's always something wrong. I swipe too fast, I don't swipe deep enough, I don't know. I always get it wrong somehow. I mean, I don't know. New Yorkers are infinitely patient, but I don't think they'll be tolerated in very many places. I don't understand why they can't just suck the card in like they do on the buses. I mean, that works every time. Yeah. So, it's a MetroCard thing. We are going to have things on MetroCard at the conference too, new things, new revelations. And if there's people out there, and I know there are, I know there are transit workers out there, transit workers on the job right now listening to us that can provide us with some information. And, of course, information is what this program, what the magazine, what the hacker culture and what the conference are all about. So, provide us with information and we'll figure things out and spread it around. Right? No harm in that? Sure. All right. Not at all. A lot of people are very afraid of that, though. A lot of people are concerned that information stays secret and behind locked doors. And that's a real danger because then you have the people who know and the people who know nothing about how things work. And it's always bad to follow things simply because you're told to. When you know how something works, you can redesign it, rethink the whole policy and come up with better ideas. So, that's kind of what we're all about. 212-279-3400. That's two random calls that worked pretty well. Yeah. Shall we try for another random call? Eventually, we're going to get somebody that calls in every week. Eventually, we'll hit craps. Yeah. All right. I'm going to try over here. No? I'm going to try over here. Good evening. You're on the air. Yes, Emmanuel. Oh. Don't call me craps, Fiber. Craps. Well. All right. I think you guys have to settle this. I just want to mention some things. We have to put you on a limit because you take up more time than anybody else on the radio, including people who are host shows. I'm not going to steal the show like I did last week. All right. I'm not going to steal the show like I did last week. We want that show back, by the way. Okay. So, please return it to us. I have it on hard disk, so I'll email it to you. No. No. Wait. Don't do that again. You already did that one. Okay. Wait. What's on your mind? Okay. Did you know that your phone number is unlisted? Do I know that my phone number is unlisted? I looked up your name, and it says, We're sorry. The number is unpublished. Oh, I'm sorry. I'll fix it for you. I'll make it listed just for you. Okay. Now, did you also know that you can make free directory assistance calls by going to a TDD, that's telecommunications device for the deaf, pay phone, and just having the 9X operator dial the 800 number of 800-855-1155. You have to say you have operator privileges, by the way, otherwise she will not dial an 800 number. And the TDD will come out, and then it'll say, May I have the number you're calling from? Give her any number you want, and it'll be billed as a directory assistance call. Don't give numbers to pay phones and stuff, because it won't work. You've got to give it to your home phone. When you say it's billed as what? Directory assistance, as if you called directory assistance from your house. Why is it billed that way? Because it's like as if you dial the 800 number from your house on a TDD, they just bill it to you. You know how that scam works, that they don't tell you that they're charging you? Right. And AT&T still puts third number calls through without asking. Even if the number is not... Blocked? Even if the number is blocked. That's Frontier. That's Frontier. Right. But will AT&T go through a block? No, AT&T won't, but Frontier will. Right. Now, you could go to Dynamics for hair. They have these desktop pay phones. You could dial AT&T and have them put calls through. And Frontier has a 950 number that you dial 9501003. And when you get the dial tone, you dial like any six digits at random. Well, not any. I mean, I like to dial like all ones or all zeros or something, like six of them. Something binary. Well, yeah. Yeah. And then you just, when the dial zero, the area cut a number. Then when the operator asks you your phone number, you say any number you want. And then you can bill to a third number. They won't do directly dial calls, but they will do third number calls. And they will not check for acceptance a lot of the time. Some of them, sometimes they will. That's fascinating. Did we not try this with Frontier last week? Yeah, I'm going to be discussing all this. And it gave a fake ring, and it never billed the person. Yeah, it gave us a busy signal for some. I mean, I was going through 9X, actually. We tried third number billing something through 9X, and it just gave us a busy signal. Then we tried it with Frontier, and they said that they couldn't. That number wasn't allowed to accept calls. Of course, we were trying to bill it to an 890 number. Yeah, different times it will do different things. I'm going to be discussing all this at Beyond Hope. I'm going to have a little, like, you know, I'm going to be speaking about things like this and how to do various tricks at Beyond Hope. Okay. And there will be all kinds of people speaking about different things. There will be lines around the block. There will be lines around the block. Did you know that with all the AT&T calls and the third number calls and whatnot you said? I'm sorry, say again? Didn't you say you got a phone bill with third number calls from AT&T and Frontier? Um, it's hard for me to remember, but that could have happened. That could have happened. You said one time that you got a phone bill from AT&T with directory assistance calls. Didn't you get a phone bill recently? I think a while ago there was something with overseas information, but that's not what you're talking about. Right, but I'm talking about, like, third number calls, like, you know, from Frontier and all these calls from New York City and from AT&T charging one call to the phone to the next. Yeah, that I can't say off the top of my head. But I do know a few months ago there was something with overseas information, which we weren't able to figure out how that happened. Well, that's how it is. Didn't you get that recently? Because that's how this happened. Uh-huh. Well, there was something a few months ago, but what you're talking about is domestic information, not overseas information. Well, no, any information, overseas, domestic. But how would you bill something overseas information? That doesn't make any sense. You just use that TDD number, and you could call any information, whether it's local information or... Wait, you mean you call the 800 number, and you tell them you need a number in France, and then they bill you for a call to information in France? Right, or you need a number in California, and they'll bill you for that. Uh-huh. Interesting. But, of course, you would need a TDD phone to do this. Well, there's a lot of TDD pay phones. They're in, like, all over the city, actually. It's the phone with the little thing on the bottom. Aren't most of those locked up? No, when it hears the TDD tone, it opens up. I see. And I'll be discussing all this at home. And anybody can e-mail me at rebel at escape.com. How is that spelled? I was going to ask about that, yes. Yeah, that's spelled E-S-C-A-P-E dot C-O-M-R-E-B-E-L at escape.com. Okay, I think, and, of course, your website, too. Well, actually, you know, if you go to my website, you'll find something very interesting. Ah, okay. Which I've put up. Well, then why don't you go there and look at something interesting. www.escape.com slash tilde rebel, right? Right. Okay. Discussing all this at Beyond Hope. Yes, I think you may have to. All right. We'll be asking a lot of questions, pointed questions. Thank you very much for calling in. I think we should have a general disclaimer for this show that we don't really endorse the defrauding of facilities that were meant for deaf people. No, that's certainly true. I kind of have a moral problem with that. I like knowing exactly how things are done. Right. But, I mean, to actually go there and do these things, you're risking a lot and you're not really getting that much out of it. It's great to discover something and then to show people, you know, how it works. And hopefully people get a clue, you know, as to what not to do in the future. But you're opening yourself up to a world of problems. And plus, in this particular way, you're victimizing somebody at the same time. Like, you know, when you use a red box, even though red boxing is so incredibly simple and everybody in the world does it. I've seen old ladies doing it. I have. You know, it's so simple. You hold a box up to the phone. It says beep. The phone says, oh, that's a quarter. Thank you. You know, what could be more simple than that? That is the ultimate in billing to nobody because you're billing a call to a pay phone that's owned by the phone company. Who's going to get a bill? No one's ever going to get a bill. They're going to get upset. They're going to say, you know, we didn't get as much money that we should have, maybe, if they even keep track. But when you third number bill to somebody, that's somebody, a person, that gets a phone bill. Oftentimes they have trouble convincing the phone company they didn't actually do it themselves. And it just creates all kinds of frustration and hard feeling. You know, you definitely have a human victim there. Now, you can say, yeah, the red box thing is all fine and good, but you're still stealing. I don't really see it as the same as actually taking money from somebody or from some organization. They run these things. There's all kinds of internal things I'm sure they do to justify charging a certain amount of money. But the fact is pay phone calls are ridiculously overpriced. It costs something like $2.40 for the first minute to call New Jersey from New York, whereas from your house it would cost $0.10. There's not that much going on in the pay phone other than collecting the coins that requires that kind of technology. Well, for that matter, why does it cost 150% more to make a local call? It's $0.10 to make a local call at home. It's $0.25 to make a local call at a pay phone. Subject to even now, they have their own zones divided up as to what's local at a pay phone, which are totally different. And if that's not enough for you, consider this. When they ask for more money, when you have five minutes or three minutes or whatever, and they ask for more money, and you put a quarter in, they only count it as a nickel. Supposedly they can't tell the difference between a quarter and a nickel in that mode. Or a dime and a nickel for that matter. Yeah, everything is a nickel. Now, come on, they obviously know the difference between a quarter and a nickel and a dime, because otherwise they wouldn't be able to collect the money in the first place. Yeah, they use a different computer system, but they could easily cut over to that for overtime charges. So many people put in whatever they have in their pocket. That's the whole point. Yeah. It's random profit. That is something that I think, yeah, they get all this extra money that they're not entitled to. Where is that ever accounted for? You know, they have such careful accounting saying, oh, this person red boxed here and stole this amount of money from us. Do they also keep records as to how much money they take from people that they don't refund? Someone puts a quarter in when they actually owe a nickel, they don't get 20 cents back. No. You know, that's, what is that? What do you call that? I call it 20 cents robbed from the person that they are never going to get back. I think we should call that red box credit. Yeah. It balances out. Now, what happens? I mean, have you ever tried doing this? You call the operator and said, yeah, I put in 20 cents too much in the phone. How do I get that back? That's a good way to get a good laugh out of an operator. I don't think they have anything. Well, you can call 211. You can call 211. They generally give you credit for almost anything you ask for. Yeah. But the reason they do that is because they have so much money in the first place. Right. It's easier for them to give it out than to argue with you because, you know, it's so trifling to them. And if there was any cause for argument, you could just tell them, well, you saw somebody that was using the phone before you and they put in two quarters and obviously the second one was only counted as a nickel. Right. So there's the 20 cents that they could send you back. Now, everybody there, ask yourself, how many times has that happened to you? And, you know, it's something to consider. Just a better reason to get a mobile phone. No, I don't think so because mobile phones are still not competitively priced. They really aren't. Mine is. Well, okay. Give me some rates here. Okay. I pay $79.99 a month. Uh-huh. Okay. That's practically $80. Practically? Wow. Yeah. Okay. Actually, I should get that extra penny that was on that guy's mom's MetroCard. But anyway, for $79.99 a month, I get 300 free minutes. Okay. Incoming or outgoing. Yeah. See, that's the thing. You have to pay for incoming minutes, too, you know? Well, all cellular phones are that way. Yeah, I know. That's why I don't like them because you pay for... Look, up till now, you never had to pay for incoming. What's the deal? Okay. If you want a wire which is finite space, like, it doesn't cost anything to use that. But to use the airwaves, which is the entire, you know, sky, you have to pay money to use those. Why are they... Why does that cost money? Explain that. Well, let me explain. Yes. You can lay wires with city permission. Right. Basically, wherever you like. Right. Okay? If you want a frequency allocated to you, the FCC divvies up the electromagnetic spectrum, and the bandwidth of a particular band that might be used for cellular communications is only so big. Only so big? Only so big. What have we run out of? What frequencies have we ever run out of? There's always a way to make more frequencies. Well, yeah. It's the electromagnetic spectrum, for God's sake. It never ends. Come on. I agree with you 100%, but it would be the equivalent of saying... Let's find a good analogy. Take a piece of paper, right? Okay. And let's say that you have a box of crayons. Okay? Okay. How easy would it be for you to draw a blue dot anywhere on that piece of paper? I happen to have both right here, so it's very easy for me to draw a blue dot on a piece of paper. It's easy, right? Yes. It's like laying wires anywhere you want, because you're, you know, a land-based communications company. Okay. Okay? Now, contrast that with... Say, for example, that in order to show somebody a blue dot, you have to shine it on the wall. Okay? Now, how easy is it for you to shine a blue dot on the wall? Well, if I have a blue dot shiner, it's very easy. Well, yeah, okay. I don't have that with me. Right. But how much does it cost to have a blue dot shiner? I don't know. I've never had one. Well, it costs more than a box of crayons, I'm sure. Oh, yeah, I guess. Okay, well, right off the bat, the technology is obviously more expensive. Not necessarily. Yes, it is. Look, a flashlight can be cheap, all right? I get flashlights for free from some, you know, promoters. Okay, let's compare the price of a flashlight. You've got to replace the batteries now and then. Okay, a flashlight with a blob. A solar-powered flashlight. You have to replace the batteries. Solar-powered flashlight. It'll last as long as the sun. Okay. And after that, it doesn't matter. Okay, we've established you need a flashlight with a blue filter and the batteries go dead. So it's a constant expense. But two flashlights, though. You can get an infinite number of flashlights. Okay. They'll never run out. Okay, but you have one blue crayon. Uh-huh. It lasts a really long time. Yeah, but it runs out. It's gone. I don't even understand what a blue crayon has to do with a wire and what a flashlight has to do with... All right, the point is, the point is, I don't think, I think the only reason they do this is because of what the market bears. And I think once they stop doing that, as many companies have. So there you go, right there. Some companies have stopped billing for incoming calls. All right? And a lot of them only bill for after the first minute, which I think is kind of good, too. You know, then more people will start using the system. The only problem is that the companies that are doing that are the companies that are going to be dead in another year or two. Because those are the same companies that are using the same analog technology that's been around since the early 80s. Right. Which allows people to clone and eavesdrop and so on and so forth. And the phones are really big and really cheap. Can you clone Sprint PCS? Can you clone AT&T PCS? Oh, funny you should ask that. Okay. Because to this day, GSM is still the only mobile phone protocol whose encryption has not been exploited. Yet. Yet. And I will agree with you that there probably will come a day when the weaknesses will become known. But at this particular point in time, even if you wanted to say, okay, GSM, I've reviewed the technology, and I think it's weak here, here, and here. Okay? But, all right. Now, let's say, what's the lesser of two evils? Let's compare the encryption that GSM uses with the stuff that digital cellular, the other digital cellular standards use. Like TDMA and CDMA. Yes. Okay. TDMA does not encrypt anything. Okay? There's some questionable scrambling which should be put in very bold-faced quotation marks. But it's not by far encryption. CDMA uses some hashing, but there's been some published white papers on the weaknesses and exploitability of the so-called security used in CDMA. So basically you're saying GSM is more secure. GSM stands alone as, to date, the most secure mobile phone protocol. And I think that's all fine and good. But I don't think it's enough. I think they have to lower their prices as well to get people to start using it. Well, I agree with you. And ultimately, when there is no more analog cellular, which is going to happen. Right. Because it's really antiquated technology that I don't think most people have the patience for. Well, they have to get all those antennas up for all the other ones. Yeah. Unfortunately, with PCS, you need all these antennas mounted on the rooftops. I still see OmniPoint putting out these brochures saying that they're going to be on Long Island in the summer of 1997. Well, guess what, folks? It's summer of 1997 now. It's the middle of it, and I don't see any... It's not over until the fat lady sings. Yeah. Well, the fat lady is on the stage, and she's warming up, so they better get to it. The other thing is I've heard some other advertising finally countering OmniPoint's 100% digital, 0% hassle thing. Oh, really? I haven't seen any of those. Yeah. And actually, it's kind of good. It's like, use our system because you can use it in more places than these people. How good is a 0% hassle phone if it's out of range, which it is in many, many places? Well... Now, that's obviously a temporary thing. Yeah. Eventually, they won't be out of range, but it is significant. That's subject to argument. Unfortunately, the United States is one of the last places on the face of the planet to get GSM technology... Right. ...because the industry here is so backwards. Well, that's true, but the thing is, the fact is that it is a lot harder to use these phones if you travel around, especially in the metropolitan area, as opposed to other ones where you can get signals virtually anywhere. Well, what do you consider the metropolitan area? I could get signal almost anywhere in New York City. New Jersey? New Jersey, yeah. Connecticut? Connecticut, I don't know. And Long Island. Long Island, you can't get in? Long Island, yeah. Long Island to date, there's only Western Nassau that's covered. Yeah, and by Western Nassau, that's like, you know, if you can jump, you're in Queens. That's what they mean by that. All right, let's see if we can squeeze in one or two more phone calls. Good evening, you're on the air. Hi, how you doing? How you doing? Not bad. Okay, I got a story for you. Okay, let's hear it. I got caller ID, and I get a number that flashes on my caller ID box last week. Area code 0-0-0. Uh-oh. 0-0-0. Uh-oh. 0-0-3-4. 0-0-3-4? 0-0-3-4. We were about to say it was all zeros. Ah, all nines. All nines, but not all zeros. 0-0-3, okay, who was on the phone? It was Line-X. Okay, now, this is what happened. Okay. Girl calls me up, and she asks for me personally. I say, who's calling? She says, Tina. I go, what is this in reference to? She says, you know, she didn't say it was from Line-X, but she said, you know, that she wanted to speak to me. I said, well, this individual's not home. Was she known as number 34 by chance? No, she didn't say anything. She just said, Tina, Tina. All right. All right. So, I says, you know, well, what is this in reference to? She says, well, I need to discuss that with this person. So, I says, well, give me a phone number that I can call you back at. It was an 8-9-0 number. Okay. So, you know what that means. Lots of times, people getting calls from 8-9-0 numbers get weird things on their caller ID boxes. Once, I got something from Exchange 215 on Long Island. This was before Long Island had 1-plus dialing, so there's obviously no way there could have been a 215 exchange because you would have gotten Philadelphia. Yeah, that's a nine eccentrics number. Yeah, so they somehow are able to put whatever data they want. I imagine because they're the phone company, they can get away with this. Well, the reason they were calling was because I was a little bit late on a payment. First time in 15 years. And, you know, the way they called, it just seemed to me like they were trying to trick me into going, yeah, I'm this person because she sounded cute. Well, they're the phone company. They know who you are. Yeah. Right, so you don't have to worry about that. But, yeah, that's interesting, and if people don't mind engaging in a little experiment, it won't hurt you. It didn't hurt you because your credit rating was not affected and 9-X doesn't care as long as they get their money eventually. But just, you know, try paying your bill a little bit late, have caller ID, and wait for that call to come in and see what number shows up. Uh-huh. Well, I got another horror story for you from 9-X. Okay, it's going to have to be quick. All right. I also have anonymous call reject. Most pay phones will not go through to it, even if you dial star A2, and it just keeps eating quarters and eating quarters, and star A2 doesn't work on most pay phones. Are you telling me that pay phones keep your money if you get an anonymous call rejection message? Absolutely. And then when you dial a star A2 to try it again, it eats your money again and still doesn't let you do it. That's completely wrong. You know, there are a lot of things wrong with pay phones in New York City, in the metropolitan area, and I think we as listeners of this show and as people in this city have to get together and do something about it, because the way they cut off your touch tone. Today I was making phone calls using one of my 800 numbers that has a big long calling card on it, and I was able to get the last digit out, and it said no additional dialing allowed. I was able to make the phone call, but then the phone call went to one of these automated things. I said press 1 for this, press 2 for that, and I couldn't press anything. I had to sit there and wait for the operators as if I was a person with a rotary phone. That's why you need to carry a tone dialer. You know how they talk to people like that. Yeah, it's really, there's no reason for them to do this at all. It's gotten to the point where I use CoCots now instead of 9X phones, because they don't cut off your touch tones. Sir, we are out of time. Sorry to cut you off, but keep the faith there as far as questioning 9X and noticing things like that. We'll be back again next week with another exciting show. Stay tuned to the website for updated information on the conference, www.hope.net. Remember the conference is August 8th, 9th, and 10th, Park Building, New York City. Just show up at this point, unless you want to get your pre-registration form in the mail before midnight tonight. The address is, actually, call 516-473-2626 and go into the Beyond Hope mailbox, Beyond Hope bulletin board system for full pricing information and things like that. Otherwise, check the website, www.hope.net, for everything that you need there. That's it for us. We'll be back again next week. Good night. The telephone keeps ringing, so I ripped it off the wall. I cut myself while shaving, now I can't make a call. It couldn't get much worse. But if they could, they would, for they live on for the best respect the worst. I hope they understood, but they didn't know. Have you ever been curious about people? Not just a few people, but all the people on the whole planet. People eating, drinking, washing, fighting, moving, growing, loving, dying, living, full, empty, hungry, rich, flying, poor, educated, or not. There's a lot of different ways to look at being a person and at being a people. So if you're interested in people, then tune into People and the Planet, a special series this summer on WBAI, Monday evenings at 8 p.m. My name is Paul Ruwest, and I'll be your host as we talk with some of the most interesting and knowledgeable people who work in fields related to modern population concerns. From reproductive health to sustainable resources, this special series will be informative for the curious person wondering about people. People and the Planet, Monday evenings at 8 p.m.